WAND Network Research Group University of Waikato Crest Of Arms


Libprotoident is a library that performs application layer protocol identification for flows. Unlike many techniques that require capturing the entire packet payload, only the first four bytes of payload sent in each direction, the size of the first payload-bearing packet in each direction and the TCP or UDP port numbers for the flow are used by libprotoident. Libprotoident features a very simple API that is easy to use, enabling developers to quickly write code that can make use of the protocol identification rules present in the library without needing to know anything about the applications they are trying to identify.

Libprotoident supports over 400 different application protocols and this number will continue to grow over the course of future releases!

The latest version is 2.0.13 - Released on 2019/04/05

Libprotoident is now available on GitHub. If you extend libprotoident or add support for new protocols and would like your additions to make it into the next release, please don't hesitate to send us a pull request. You can also find a list of supported protocols and the release history on our GitHub wiki page.

On Mac OS X, libprotoident may also be installed using Homebrew.

We also maintain our own packages for Debian and Ubuntu (versions 2.0.13 and later only). Instructions for obtaining the packages.

NEW: Starting from version 2.0.9, libprotoident will now be licensed under the LGPL v3. Hopefully this will help some people that were previously unable to make use of libprotoident due to the restrictions of the GPL license.

All releases of libprotoident prior to 2.0.9 are licensed under the GPL v2.

Important note for developers: The libprotoident API has changed since version 1.0.0. The changes are described in the Developer Documentation page in the libprotoident wiki and the included tools have been updated to use the changed API. Please be sure to update any programs you have written based on libprotoident accordingly (the changes should be minor). If you get stuck, the source code for the tools may help clarify the differences.


From 2.0.11 onwards, libprotoident requires the following libraries:

Libprotoident has been developed and tested on both Linux, MacOS X and FreeBSD operating systems. Libprotoident will compile and run on a PowerPC system but there may be problems with some of the rules due to byte-ordering issues. If this occurs, please file a bug in the libprotoident bug tracker.


Basic usage instructions are included in the README that accompanies the source code. Additional documentation can be found within the source code itself.

The library also comes with some basic tools that demonstrate the capabilities of the library without the need for the user to develop code. The lpi_protoident tool reports the protocol for every flow observed on the provided libtrace input, for instance.


We are always interested in hearing feedback about software projects such as libprotoident. If you have any requests or comments, or wish to report a bug, please email contact@wand.net.nz or create an issue on our GitHub page.